How Long Should Your Passwords Actually Be?
Have you noticed how much stricter password requirements have gotten lately? These days, many services now require special characters in your password, and some organizations have bumped their minimum password length up to 16 characters or more. Tech-reliant companies even require their employees to change their passwords on a regular basis, and it must be a different one every time. Sure, you can use a password generator to create a complex and hack-proof password, but a complicated password might do more harm than good if you lose it and can't remember it. So how long should your important passwords actually be?
The ideal password length is between 14 and 16 characters. This coincides with the theory put forth by psychologist Nelson Cowan, who claimed that a human's working memory is limited to approximately four "chunks" at a time. This means that it's easier to remember a 14- to 16-character password if it's made up of three to five memorable chunks. And according to the password manager service Bitwarden, a 16-character password with a mix of character types would take centuries for a hacker to crack through brute force. Many account creation services still only require a minimum password length of eight characters, but in an age of new hacking threats, building longer passwords is simply safer.
How to create a memorable password that's actually safe
Longer passwords are harder to crack, but also more difficult to remember. One of the best ways around this is to create a passphrase instead of a password. This can be a short sentence you'll easily remember, or it can be a series of seemingly unrelated words separated by spaces, hyphens, or other punctuation. Think of a passphrase like a mnemonic that you can memorize by associating it with the act of accessing your account.
Phrases are often more secure than standalone words because they inherently deter dictionary attacks. A dictionary attack is when a hacker uses a program to brute-force their way into an account by attempting every commonly used word and character sequence, as well as common variations. This tactic won't work on you if your passphrase is made up of multiple words that aren't commonly used together.
But what happens when you have a dozen different passphrases, all with 16+ characters, for a dozen different accounts? Well, that's where you can still benefit from using secure password managers that users actually swear by. But it's important to take password managers with a grain of salt. One of the most common ways passwords are hacked is by looking over someone's shoulder or snooping through their phone. Malicious individuals can find your password manager on your phone, but they won't find the passwords that are locked safely in your mind.